PT-2009-1640 · Cspartner · Cspartner

Staker

·

Published

2009-02-19

·

Updated

2017-09-29

·

CVE-2008-6165

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CSPartner version 0.1
Description The issue allows remote attackers to execute arbitrary SQL commands. This is possible via the pseudo and passe parameters in the gestion.php file when magic quotes gpc is disabled.
Recommendations For CSPartner version 0.1, consider disabling the magic quotes gpc option or restricting access to the gestion.php file until a patch is available. As a temporary workaround, avoid using the pseudo and passe parameters in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6165

Affected Products

Cspartner